# Autopsy Setup Help

**URL:** <https://sleuthkit.discourse.group/t/autopsy-setup-help/3258>\
**Category:** Autopsy Stories\
**Created:** [May 31, 2022, 9:52pm UTC](https://sleuthkit.discourse.group/t/autopsy-setup-help/3258 "2022-05-31T21:52:18Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![fancy\_flare](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/fancy_flare/32/1900_2.png) [@fancy\_flare](https://sleuthkit.discourse.group/u/fancy_flare)\
**Post date:** [May 31, 2022, 9:52pm UTC](https://sleuthkit.discourse.group/t/autopsy-setup-help/3258/1 "2022-05-31T21:52:18Z")

</div>

Hopefully this is the right place and also this might end up being helpful. I’ve been documenting how I’m setting up Autopsy to use and then blogging CTF writeups using Autopsy, but wanted to share this page to see if anyone had any comments or recommendations or things that are obvious that I should add? Any feedback would be appreciated, its aimed at helping new people get using Autopsy.

You can leave comments here or you can comment on the page itself via github issues. The website is also my build and design and I’d like to think im spending more time on content 😉

> **[Getting started with Autopsy](http://fancy4n6.com/2022/05/03/Autopsy/)**
>
> It can seem daunting when starting out in DFIR and looking at all the tools and how much money might need to be expended to get a lab set up to even practice. But don’t despair, there are plenty of open source and free tools available that you can...

---

<div class="post-metadata">

**Author:** ![nika](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/nika/32/1574_2.png) [@nika](https://sleuthkit.discourse.group/u/nika)\
**Post date:** [June 6, 2022, 7:03am UTC](https://sleuthkit.discourse.group/t/autopsy-setup-help/3258/2 "2022-06-06T07:03:46Z")

</div>

Seems like it would / will be very helpful for new users in getting started. I especially find the tip on turning on WAL journaling very helpful. That one is new to me. Thanks.

You mention the drive speed being the biggest bottle neck. I find that very true. I usually read from one drive and write to another. I.e. I have my case directory on an SSD and the source image / logical files on a separate disk. This seems to speed up the process quite a bit. Even when working with (slower) spinning disks.

I hope my feedback is helpful.

---

<div class="post-metadata">

**Author:** ![fancy\_flare](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/fancy_flare/32/1900_2.png) [@fancy\_flare](https://sleuthkit.discourse.group/u/fancy_flare)\
**Post date:** [June 6, 2022, 7:36am UTC](https://sleuthkit.discourse.group/t/autopsy-setup-help/3258/3 "2022-06-06T07:36:06Z")

</div>

Hey nika, that’s excellent advice and a suggestion, do you mind if i put that onto the page as well?

---

<div class="post-metadata">

**Author:** ![nika](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/nika/32/1574_2.png) [@nika](https://sleuthkit.discourse.group/u/nika)\
**Post date:** [June 6, 2022, 8:05am UTC](https://sleuthkit.discourse.group/t/autopsy-setup-help/3258/4 "2022-06-06T08:05:57Z")

</div>

Hi fancy\_flare. No problem. You can put my answer there.

---

<div class="post-metadata">

**Author:** ![fancy\_flare](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/fancy_flare/32/1900_2.png) [@fancy\_flare](https://sleuthkit.discourse.group/u/fancy_flare)\
**Post date:** [June 6, 2022, 8:14am UTC](https://sleuthkit.discourse.group/t/autopsy-setup-help/3258/5 "2022-06-06T08:14:57Z")

</div>

thankyou so much! 🙂

---

<div class="post-metadata">

**Author:** ![nika](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/nika/32/1574_2.png) [@nika](https://sleuthkit.discourse.group/u/nika)\
**Post date:** [June 7, 2022, 7:23pm UTC](https://sleuthkit.discourse.group/t/autopsy-setup-help/3258/6 "2022-06-07T19:23:26Z")

</div>

Hello @fancy_flare, you mentioned in your [post](http://fancy4n6.com/2022/05/03/Autopsy/#WalJournaling:~:text=This%20is%20a%20tip%20that%20Mark%20McKinnon%20shared%20with%20me.) that @Mark_McKinnon shared with you a tip on turning on Wal journaling in the autopsy.db. If possible, are you able to direct me to that post (if it is available). I’d be interested.

Also, this is the first time I’ve ever seen this tip anywhere. IMHO, I think it should be built in as an option when performing in single case mode. (There may be / probably is a reason it is not.)

Again, thanks for the tip!

---

<div class="post-metadata">

**Author:** ![fancy\_flare](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/fancy_flare/32/1900_2.png) [@fancy\_flare](https://sleuthkit.discourse.group/u/fancy_flare)\
**Post date:** [June 7, 2022, 10:19pm UTC](https://sleuthkit.discourse.group/t/autopsy-setup-help/3258/7 "2022-06-07T22:19:01Z")

</div>

There is a link to the issue Mark posted in github in my writeup

---

<div class="post-metadata">

**Author:** ![nika](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/nika/32/1574_2.png) [@nika](https://sleuthkit.discourse.group/u/nika)\
**Post date:** [June 8, 2022, 1:28am UTC](https://sleuthkit.discourse.group/t/autopsy-setup-help/3258/8 "2022-06-08T01:28:24Z")

</div>

I see what happened. Your link has an “)” at the end and thus was not bringing me to the issue:

> `"https://github.com/sleuthkit/autopsy/issues/2518)"`

I found it now.

Thank you!

---

<div class="post-metadata">

**Author:** ![fancy\_flare](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/fancy_flare/32/1900_2.png) [@fancy\_flare](https://sleuthkit.discourse.group/u/fancy_flare)\
**Post date:** [June 8, 2022, 1:58am UTC](https://sleuthkit.discourse.group/t/autopsy-setup-help/3258/9 "2022-06-08T01:58:10Z")

</div>

Fixed 🙂  
And it’s why i wanted to have a central place with some recommendations as I’ve found it a bit challenging to figure out what’s what sometimes.

---

<div class="post-metadata">

**Author:** ![fancy\_flare](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/fancy_flare/32/1900_2.png) [@fancy\_flare](https://sleuthkit.discourse.group/u/fancy_flare)\
**Post date:** [October 30, 2023, 3:39am UTC](https://sleuthkit.discourse.group/t/autopsy-setup-help/3258/10 "2023-10-30T03:39:39Z")

</div>

I have updated this page a little bit and interested if anyone else has any tips they’d like to share?

> **[Autopsy Forensics](https://www.fancy4n6.com/docs/resources/tooling/autopsy-forensics/)**
>
> Getting started with Autopsy # It can seem daunting when starting out in DFIR and looking at all the tools and how much money might need to be expended to get a lab set up to even practice. But don’t despair, there are plenty of open source and free...
